Back to bug 2069625

Who When What Removed Added
Mauro Matteo Cascella 2022-03-29 09:57:56 UTC Depends On 2069627
Mauro Matteo Cascella 2022-03-29 10:04:54 UTC Summary CVE-2022-1050 QEMU: pvrdma: unchecked malloc size due to integer overflow in init_dev_ring() CVE-2022-1050 QEMU: pvrdma: use-after-free issue in pvrdma_exec_cmd()
Mauro Matteo Cascella 2022-03-29 10:06:26 UTC Blocks 2069629
RaTasha Tillery-Smith 2022-03-29 13:44:44 UTC Doc Text A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. A crafted guest driver might execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition. A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.
Product Security DevOps Team 2022-03-29 14:31:14 UTC Status NEW CLOSED
Resolution --- NOTABUG
Last Closed 2022-03-29 14:31:14 UTC
Mauro Matteo Cascella 2022-04-04 07:36:18 UTC Comment 0 updated
Marian Rehak 2022-04-28 16:04:17 UTC Blocks 2066710
Marian Rehak 2022-04-28 16:05:36 UTC Fixed In Version qemu 2.20.1
Sylvain Beucler 2023-03-09 15:52:08 UTC CC beuc
Mauro Matteo Cascella 2023-07-17 13:02:16 UTC Fixed In Version qemu 2.20.1 qemu 8.0.0

Back to bug 2069625